Release date:
Updated on:
Affected Systems:
Socat 2.0.0-b1-2.0.0-b6
Socat 1.3.0.0-1.7.2.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65201
CVE (CAN) ID: CVE-2014-0019
Socat is a command line-based tool that allows you to create two bidirectional byte streams and transmit data between them.
Socat 1.3.0.0-1.7.2.2, 2.0.0-The b1-2.0.0-b6 has a stack buffer overflow vulnerability. Local Users can exploit this vulnerability to execute arbitrary code in affected applications by using the super-long server name in the PROXY-CONNECT address in the command line.
<* Source: Florian weian (Weimer@CERT.Uni-Stuttgart.DE)
Link: http://osvdb.org/102612
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Socat
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.dest-unreach.org/socat/